Vulnerability Name: | CVE-2007-6416 (CCN-39160) | ||||||||||||||||
Assigned: | 2007-12-14 | ||||||||||||||||
Published: | 2007-12-14 | ||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||
Summary: | The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-6416 Source: OSVDB Type: UNKNOWN 41344 Source: CCN Type: RHSA-2008-0089 Important: kernel security and bug fix update Source: CCN Type: SA28146 Xen PAL Emulation "copy_to_user()" Security Bypass Source: SECUNIA Type: UNKNOWN 28146 Source: SECUNIA Type: UNKNOWN 28643 Source: CCN Type: OSVDB ID: 41344 Xen on IA64 PAL Emulation copy_to_user() Function Guest User Arbitrary Physical Memory Access Source: REDHAT Type: UNKNOWN RHSA-2008:0089 Source: BID Type: UNKNOWN 26954 Source: CCN Type: BID-26954 Xen 'copy_to_user()' Local Security Bypass Vulnerability Source: CCN Type: Xen Web site changeset: [IA64] Fix vulnerability of copy_to_user in PAL emulation Source: CONFIRM Type: Exploit http://xenbits.xensource.com/ext/ia64/xen-unstable.hg?rev/e6069a715fd7 Source: XF Type: UNKNOWN xen-copytouser-security-bypass(39160) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9840 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |